Security & Privacy
Your business decisions are sensitive. Here is how we protect them.
Data Isolation
Every organization's data is strictly isolated. Cross-tenant access is prevented at the database query level. Your decisions, memory, and files are never accessible to other organizations.
Encryption in Transit
All traffic is encrypted in transit over TLS. API keys and secrets are stored server-side only and are never exposed to browsers or client-side code.
Access Controls
Role-based access (Owner, Admin, Editor, Viewer) with server-side enforcement. Every API request verifies session, membership, and role before processing.
Audit Logging
Significant actions are recorded in audit logs — decision creation, test runs, team changes, billing events. Logs never contain secret keys or full business content.
AI Transparency
Every AI finding is tagged with its source type: user-provided data, model inference, or unverified assumption. No statistics or market data are fabricated.
Managed Infrastructure
Hosted on managed cloud infrastructure with regular platform-level database snapshots. Stripe handles all payment processing — card details never touch our servers.